[PATCH v2 0/3] media: uvcvideo: harden the frame buffer size computation
From: Natasha Klaus
Date: Thu Aug 20 2026 - 06:48:16 EST
uvc_parse_frame() recomputes dwMaxVideoFrameBufferSize for uncompressed
formats from three descriptor fields that nothing validates. The product
is evaluated in 32-bit signed arithmetic, so it wraps, and the driver
stores a size that is usually far too small and sometimes exactly zero.
Noam Ben Shimon reported and fixed the overflow. Reviewing it surfaced a
second route to a zero size, and Ricardo Ribalda asked for a series
rather than two independent patches, so the two cases are not handled
inconsistently.
1/3 changes the return convention of uvc_parse_frame() so it can
report "skip this frame descriptor" separately from a fatal
error. Suggested by Ricardo.
2/3 Noam's overflow check, adapted to skip rather than reject, with
DIV_ROUND_UP_ULL and the operand values in the diagnostic per David
Laight's review.
3/3 the zero-size case.
On stable: 1/3 carries Cc: stable with no Fixes: tag of its own. It is a
prerequisite, since 2/3 and 3/3 need -EINVAL to mean "skip". Backporting
2/3 without 1/3 is not broken, it reverts to discarding the streaming
interface, but the commit message would then describe something the
backport does not do. Both or neither, please.
Carrying 2/3 on Noam's behalf, with his agreement on the list.
Build tested on x86_64 only, no hardware and no UVC gadget.
Changes in v2:
- 1/3: check -ENODATA before counting the frame (Ricardo Ribalda)
- 2/3: DIV_ROUND_UP -> DIV_ROUND_UP_ULL (Ricardo Ribalda)
- Reviewed-by from Ricardo Ribalda added to all three
Natasha Klaus (2):
media: uvcvideo: Let uvc_parse_frame() report a skipped frame
media: uvcvideo: Skip frame descriptors with a zero computed size
Noam Ben Shimon (1):
media: uvcvideo: Fix integer overflow in frame buffer size calculation
drivers/media/usb/uvc/uvc_driver.c | 52 ++++++++++++++++++++++--------
1 file changed, 39 insertions(+), 13 deletions(-)
--
2.34.1